3 ms·
If you sanitize on the server, you are sanitizing for a theoretical browser and how _you_ might think it parse HTML. Any kind of parsing ambiguity will lead to
by bugmen0t 5y ago
If you sanitize on the server, you are sanitizing for a theoretical browser and how _you_ might think it parse HTML. Any kind of parsing ambiguity will lead to XSS.
That's why you should be using an API that relies on the browser's parser.